"""Email for the staff password-reset flow.

Uses ``fail_silently=True`` in line with the rest of the project — a misconfigured
mail server must never leak (via a 500) whether an account exists.
"""
import logging

from django.conf import settings
from django.core.mail import EmailMessage

logger = logging.getLogger(__name__)


def send_password_reset_email(user, reset_url: str) -> None:
    """Email a password-reset link to a staff user."""
    if not user.email:
        return

    name = user.get_full_name() or user.get_username()
    subject = 'Reset your SirObix password'
    body = (
        f'Hi {name},\n\n'
        f'We received a request to reset the password for your SirObix '
        f'management account.\n\n'
        f'Click the link below to choose a new password. It expires in a few hours '
        f'and can only be used once:\n\n'
        f'{reset_url}\n\n'
        f'If you did not request this, you can safely ignore this email — your '
        f'password will not change.\n\n'
        f'SirObix\n'
    )
    try:
        EmailMessage(
            subject=subject,
            body=body,
            from_email=settings.DEFAULT_FROM_EMAIL,
            to=[user.email],
        ).send(fail_silently=True)
    except Exception:  # pragma: no cover - defensive
        logger.exception('Failed to send password-reset email')
